> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pavoai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

Pavo is built for production systems in security-conscious organizations. Three principles govern every data flow, in every deployment model:

* **Read-only ingestion.** Connectors pull from your sources; nothing is ever written back to your systems.
* **No training on your data.** Customer data is never used to train models — by Pavo or by any model provider. External LLM providers operate under zero-data-retention (ZDR) terms.
* **Everything disclosed.** Every component and sub-processor is documented; optional integrations are individually gated per instance and disabled unless you enable them — in both deployment models.

## Certifications & assurance

| Certification / assurance | Status                                                                                                                                                                        |
| :------------------------ | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **SOC 2 Type II**         | Certified — Security Trust Services Criteria, covering the Pavo-hosted platform. Report available under NDA.                                                                  |
| **ISO/IEC 27001**         | Certified — information security management system (ISMS), with an approved policy set covering information security, data handling, retention, incident response, and BC/DR. |
| **DPAs**                  | Every sub-processor operates under a Data Processing Agreement; the list for your deployment is finalized in the DPA annex.                                                   |
| **Zero data retention**   | External LLM providers (OpenAI, Anthropic) run under ZDR agreements — prompts and completions are not stored and are never used for training.                                 |
| **Penetration testing**   | Annual, independent, third-party. Executive summary shared under NDA.                                                                                                         |

## Data handling & lifecycle

All customer data is classified **Confidential** by default under Pavo's data classification policy (Public / Internal / Confidential / Restricted; unlabelled data defaults to Confidential). Encryption is AES-256 at rest via cloud KMS and TLS 1.2+ in transit; customer-managed keys (CMEK) are available in both deployment models.

| Data                                     | Retention & disposal                                                                                                                              |
| :--------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------ |
| Customer content (raw + processed)       | Retained for the subscription term. On termination: 30-day export window, then deletion within 30 days — or earlier on verified deletion request. |
| Prompts & completions at model providers | Not retained — zero-data-retention agreements; never used for training or model improvement.                                                      |
| Operational logs                         | Retained 12 months per logging policy; operational telemetry only.                                                                                |
| Backups                                  | 90-day rolling; multi-AZ within a single region — no cross-region replication, preserving data residency.                                         |
| Disposal                                 | Media sanitization per NIST SP 800-88.                                                                                                            |

## Identity & access

* SSO through your identity provider (OIDC); least-privilege access with audit logging throughout.
* MFA mandatory for all production and administrative access; access reviews at least annually; access revoked immediately on termination.
* No standing engineer access to customer environments — support access is time-boxed, authorized, and audited.

## Network & egress

* No public data endpoints; network isolation throughout.
* Agent-executed code runs in a sandbox behind a **default-deny egress allowlist proxy**. The allowlist is tiered: a minimum tier (open-source package registries needed for data/ML work), an opt-in tier enabled only with your approval, and customer-specific entries for your own cloud endpoints. The full allowlist is available on request and agreed per deployment.

## Platform hardening

* Signed images verified at admission; SSH disabled by default.
* Monthly infrastructure and application vulnerability scans plus continuous dependency scanning; patch SLAs: Critical 24h · High 7d · Medium 30d · Low 90d.

## Incident response & resilience

* Documented incident response with a defined escalation chain and a named CISO and Data Protection Officer. Breach notification without undue delay — target within 72 hours of confirmation, aligned with the GDPR supervisory standard. Data subject requests answered within one month.
* Business continuity: RTO 4 hours, RPO 1 hour. Backups at least weekly plus database snapshots, multi-AZ within a single region; restoration tested at least annually.

## Requests

The SOC 2 Type II report, ISO/IEC 27001 certificate, penetration test executive summary, DPA and sub-processor annex, full reference architecture for VPC deployments, egress allowlist, and any policy from the ISMS set are available on request:

**Srijan Saket — CISO & Data Protection Officer · [srijan@pavoai.com](mailto:srijan@pavoai.com)**

## Next steps

<CardGroup cols={2}>
  <Card title="Sub-processors" icon="list" href="/security/sub-processors">
    Every third party, the data it processes, and how it runs per deployment.
  </Card>

  <Card title="Deployment options" icon="scale" href="/deployment/overview">
    Compare Pavo Cloud, Customer VPC, and Hardened VPC side by side.
  </Card>
</CardGroup>
